Fraud prevention watches your checkout for signs of automated or malicious shopper behavior — card testing, bot-driven checkout attempts, and similar abuse. It records what it sees, and, when you turn on automatic blocking, it stops the attempts it flags before they become orders.
Fraud prevention is free and is included with your store. There is nothing to install or purchase.
Availability. Fraud prevention is currently available on WordPress.com stores running on WP Cloud. It is not yet available on other hosting platforms.
What it does not do. Fraud prevention looks for automated and malicious shopper behavior. It is not a complete fraud solution. It does not score individual buyers for credit risk, does not detect friendly fraud or chargeback abuse, and does not replace the fraud controls your payment gateway provides.
Early access and automatic enablement
↑ Back to topFraud prevention is rolling out in two stages.
Now — early access. Fraud prevention is evaluating checkout attempts on your store and recording what it finds, but it is not blocking anything. You can turn on automatic blocking whenever you are ready.
On October 20, 2026 — automatic enablement. Automatic blocking will be turned on by default for eligible stores.
You have three options:
- Turn it on now. Select the automatic blocking checkbox in settings. You will start blocking flagged attempts immediately.
- Do nothing. Automatic blocking turns on for you on October 20, 2026.
- Opt out. Select Opt out of automatic blocking in the settings notice. Your store will be excluded from automatic enablement on October 20, 2026, and automatic blocking stays off until you turn it on yourself.
Opting out is reversible at any time — just select the checkbox in settings.
If you turn automatic blocking off after it has been auto-enabled on October 20, 2026, it stays off. It will not be turned back on for you.
How fraud prevention works
↑ Back to topEvaluation
When a shopper reaches a supported checkout flow, fraud prevention evaluates the attempt in real time using browser and behavioral signals. Each attempt gets one of these results:
| Result | What happens |
| Not flagged | Checkout continues normally. |
| Flagged, automatic blocking off | Checkout continues. The attempt is recorded as Allowed with a Flagged badge. |
| Flagged, automatic blocking on | Checkout is stopped. The attempt is recorded as Blocked. |
| Matched one of your rules | Your rule decides the outcome, whatever the automated result was. |
Evaluation continues even when automatic blocking is off
↑ Back to topThis is the most important thing to understand about the setting. The Automatically block checkout attempts flagged by fraud prevention checkbox controls blocking only. It does not control evaluation.
With the setting off:
- Checkout attempts are still evaluated.
- Checkout attempts are still recorded and appear in your checkout attempts list.
- Your allow and block rules still apply.
- Nothing is blocked automatically.
This is deliberate: it lets you see what fraud prevention would have caught before you let it act.
Fraud prevention fails
↑ Back to topIf fraud prevention cannot complete its checks, the checkout attempt is allowed through. A service outage or a network problem will never stop your customers from buying. It may mean some attempts are not recorded.
A block applies to one attempt only
↑ Back to topBlocking stops the checkout attempt in front of it — not the shopper, and not their session. If the same shopper tries again, the new attempt is evaluated from scratch and may well succeed. A false positive is recoverable without any action from you.
What the shopper sees
↑ Back to topA blocked shopper sees a neutral message that does not mention fraud:
We are unable to process this request online. Please contact support (your store’s email address) to complete your purchase.
The email address comes from your WooCommerce email settings, falling back to your site’s admin email. Make sure it is an address you monitor — it is the only route a wrongly blocked customer has back to you.
Finding fraud protection in your store
Go to WooCommerce → Settings → Fraud prevention.
The page has three sections:
- Fraud prevention — the automatic blocking setting and, during early access, the opt-out notice.
- Rules — create a rule, or go to your rules list.
- Performance — a 30-day summary, with a link to your checkout attempts.
Turning on automatic blocking
On WooCommerce → Settings → Fraud prevention, select Automatically block checkout attempts flagged by fraud prevention, then select Save.
While automatic blocking is off, the card shows a notice telling you what you are missing, for example:
12 checkout attempts were flagged as suspicious in the last 30 days but allowed because automatic fraud prevention is off. We will turn on blocking by default on October 20. You can turn it on now using the setting above, or opt out of this new feature.
The count links to your checkout attempts list, filtered to those attempts, so you can see exactly what would have been blocked before you decide.
Before you turn it on, it is worth reviewing those flagged attempts. If any of them look like real customers, create an allow rule for them first. If your store has a staging site, you can also enable the setting there and place a few test orders to confirm your checkout behaves the way you expect.
After you turn it on, check your checkout attempts list over the next few days. Anything blocked in error can be fixed with an allow rule, and the shopper can simply try again.
Performance
↑ Back to topThe Performance card summarizes the last 30 days:
| Metric | Meaning |
| Flagged by fraud prevention | Attempts flagged as suspicious but allowed, because automatic blocking was off. Shown only while automatic blocking is off. |
| Blocked automatically | Attempts blocked by fraud prevention. |
| Allowed by rules | Attempts allowed because they matched one of your allow rules. |
| Blocked by rules | Attempts blocked because they matched one of your block rules. |
Once automatic blocking is on, Flagged by fraud prevention disappears — flagged attempts are now counted under Blocked automatically.
Select View checkout attempts for the detail behind these numbers.
Checkout Attempts
↑ Back to topWooCommerce → Settings → Fraud prevention → View checkout attempts
This is the record of every checkout attempt fraud prevention evaluated, newest first, for the last 30 days. Older attempts are deleted automatically.
Columns
| Column | Notes |
| Provider | The payment gateway used for the attempt. |
| Date and time | Shown in your browser’s time zone. |
| Customer email | Shows an Allow rule or Block rule marker if one of your rules currently targets this address. |
| IP | Same rule marker as above. |
| IP location | Country resolved from the IP. Context only — you cannot write rules on it. |
| Billing address | Country, city, and postcode. Context only — you cannot write rules on it. |
| Outcome | See below. |
Outcomes
| Badge | Meaning |
| Allowed | Not flagged. Checkout proceeded. |
| Allowed + Flagged | Fraud prevention considered the attempt suspicious but allowed it, because automatic blocking was off at the time. Select the information icon for an explanation and a link to the setting. |
| Blocked | Blocked automatically by fraud prevention. |
| Allowed by rules | Matched one of your allow rules. |
| Blocked by rules | Matched one of your block rules. |
In the Outcome filter, the flagged-but-allowed case appears as Allowed, flagged.
Finding things
- Tabs: All, Allowed, Blocked.
- Search: by email or IP.
- Filters: Provider, Outcome, and Merchant rule (With matching rules / Without matching rules).
- Sorting, filters, and layout preferences are remembered between visits.
What you will not see
Fraud prevention does not show you the individual signals behind an automated decision, and it does not show a risk score. This is intentional — publishing the signals would tell attackers how to work around them.
A note on rule markers
The Allow rule / Block rule marker next to an email or IP reflects your current rules, not what happened at the time. If you create a rule today, it appears next to matching older attempts — but it did not affect them. Historical outcomes never change.
Rules
↑ Back to topRules are exact allow and block instructions you write yourself. They override whatever fraud prevention decides.
WooCommerce → Settings → Fraud prevention → Rules (or View rules).
What a rule can match
Each rule matches one exact value:
- an email address — for example, j.holland@gmail.com
- an IP address — IPv4 or IPv6, for example, 111.111.111.111
Rules do not support wildcards, domains, ranges, or partial matches. You cannot write rules on IP location or billing address.
How rules are applied
Rules are evaluated in this order:
- A matching allow rule wins. If an attempt matches both an allow rule and a block rule, it is allowed.
- A matching block rule wins over the automated decision.
- If no rule matches, the automated decision applies.
Three consequences worth knowing:
- Rules apply even when automatic blocking is off. Turning the setting off does not pause your rules.
- Rules apply regardless of payment gateway.
- Rules apply to future attempts only. Creating, editing, or deleting a rule never changes a past attempt or an existing order.
Creating a rule
From Settings → Fraud prevention, select Create rule, then choose:
- Action — Allow or Block
- Rule type — Email address or IP address
- Value — the exact address
Select Create rule to save. You are taken to the rules list, where the new rule appears.
If a rule for that value already exists, you will be told, and offered Edit existing rule instead of creating a duplicate.
Creating a rule from a checkout attempt
This is usually the faster route, and it avoids retyping customer data.
In the checkout attempts list, open the row’s actions menu. What you are offered depends on the row:
| Situation | Available actions |
| Attempt was blocked, no rule yet | Allow this email address / Allow this IP address |
| Attempt was allowed, no rule yet | Block this email address / Block this IP address |
| A rule already matches | Edit email address rule / Delete IP address rule, and so on |
| Flagged but allowed, automatic blocking off | Turn on automatic fraud prevention, plus the actions above |
The value is filled in from the attempt and cannot be changed — confirm and save.
Note the last row. When fraud prevention flags an attempt and you have automatic blocking off, the right fix is usually to turn automatic blocking on, not to write a one-off block rule. A block rule only stops that one email or IP; an attacker rotating addresses will get straight past it.
Editing and deleting rules
In the rules list, use Edit or Delete on any rule.
Deleting is straightforward: “This rule will no longer apply to future checkout attempts. Past attempts won’t be affected.” Your checkout attempt history stays intact.
Best practices
- Keep your rule set small. Rules are exact matches and they override the automated system. A large rule set is hard to reason about and gets stale.
- Be careful with IP rules. An IP address is often shared — by a household, an office, a school, a mobile carrier, or a VPN. A block rule on an IP can block people who have nothing to do with the attempt you saw. Prefer an email rule where you have a choice.
- Use allow rules for known-good customers, particularly repeat wholesale or B2B buyers whose ordering patterns can look automated.
- Use block rules for confirmed abuse you have already investigated.
- Do not use block rules as a substitute for automatic blocking. Rules handle the cases you already know about. Automatic blocking handles the ones you do not.
- Revisit your rules periodically. Rules stay in force until you edit or delete them.
What is Covered
↑ Back to topCheckout flows
Fraud prevention evaluates these flows:
- Checkout block (the default WooCommerce checkout)
- Classic (shortcode) checkout
- Pay for order pages
- Add payment method (My Account)
- Change payment method for WooCommerce Subscriptions
- PayPal Payments express and smart buttons — product page, cart, mini-cart, checkout, and pay-for-order — plus card fields and saved-payment-method setup
Recording and protection depend on the attempt reaching fraud prevention. Heavily customized checkouts, headless storefronts, and unsupported payment flows may not be recorded or protected. If your store uses a custom checkout, review your checkout attempts list to confirm attempts are being recorded before you rely on automatic blocking.
Payment gateways
Fraud prevention records attempts from all gateways that reach it, and shows the gateway in the Provider column so you can see the coverage on your own store.
Your rules apply across every gateway.
Data and Privacy
↑ Back to topTo evaluate a checkout attempt, fraud prevention collects and sends checkout information to the internal verification service, and records it on your store.
What is recorded, when available:
- Customer email address
- IP address and the country resolved from it
- Billing address country, city, and postcode
- Payment gateway and payment method type
- Cart and order details, such as items and totals
- Browser and behavioral signals from the checkout session
- The outcome, and any rule that matched
Reporting: You can view your last 30 days of checkout attempts at WooCommerce → Settings → Fraud prevention. This applies whether automatic blocking is on or off.
When automatic blocking is off, attempts are still evaluated and still recorded, with the same information and the same 30-day view.
Troubleshooting
↑ Back to topA real customer was blocked.
Ask them to try again — each attempt is evaluated separately, and a repeat attempt often succeeds. If it does not, find the attempt in your checkout attempts list and create an allow rule for their email address from the row’s actions menu. They can then complete the order.
I am seeing flagged attempts but nothing is being blocked.
Automatic blocking is off. Go to WooCommerce → Settings → Fraud prevention and select Automatically block checkout attempts flagged by fraud prevention.
Nothing is appearing in my checkout attempts list.
Either no checkout attempts have been made in the last 30 days, or your checkout flow is not one fraud prevention evaluates. See “What is covered”.
My rule does not seem to work.
Check three things: the value is an exact match (rules do not support wildcards or partial matches); there is no allow rule for the same shopper, since allow always wins; and the attempt happened after you created the rule, since rules never apply retroactively.
I blocked an IP and now other customers cannot check out.
IP addresses are frequently shared. Delete the IP block rule and use an email block rule instead.
I want to stop automatic blocking.
Clear the checkbox on WooCommerce → Settings → Fraud prevention and select Save. It will stay off. Your rules continue to apply.
Getting Help
↑ Back to topIf you have questions about fraud prevention on your store, contact WooCommerce support through your store’s support channel.
Questions and support
↑ Back to topDo you still have questions and need assistance?
This documentation is about the free, core WooCommerce plugin, for which support is provided in our community forums on WordPress.org. By searching this forum, you’ll often find that your question has been asked and answered before.
If you haven’t created a WordPress.org account to use the forums, here’s how.
- If you’re looking to extend the core functionality shown here, we recommend reviewing available extensions in the WooCommerce Marketplace.
- Need ongoing advanced support or a customization built for WooCommerce? Hire a Woo Agency Partner.
- Are you a developer building your own WooCommerce integration or extension? Check our Developer Resources.
If you weren’t able to find the information you need, please use the feedback thumbs below to let us know.